Turkey Spotlight
CASP frameworkTurkey moved from a 2021 payment ban to a full licensing regime in just three years — and built the most technically prescriptive crypto-security bar of any major market. This view traces that lineage, shows what inspired each step, and maps every requirement to where CertiK can help.
The opportunity score blends deadline urgency, applicable-service breadth and market maturity at the jurisdiction level. The CASP licensing regime detailed below is established by Law 7518 — which is why the framework reads as "Licensing" even where the aggregate jurisdiction record is still catching up.
The TÜBİTAK bar: a now-live, state-grade security standard
Turkey is the only major jurisdiction to route crypto-platform licensing through a national cybersecurity laboratory. Under Law 7518 Art. 35/B(2), the IT-systems criteria for a CASP licence are set by TÜBİTAK BİLGEM, and Art. 99/B(2) makes an independent IT-systems audit mandatory. This is no longer a pending framework: SPK Communiqués III-35/B.1 and III-35/B.2 — covering establishment, operating principles and capital adequacy — entered into force in March 2025, and TÜBİTAK BİLGEM technical guidelines set concrete controls: FIPS 140-3 / ISO-19790 Level-3 HSMs (Level 2 is insufficient), cold-wallet dominance, MPC / multi-signature custody with at least one key share in a certified HSM, keys generated inside a secure element and never extracted, and in-country hosting of critical infrastructure. The platform-revenue levy under Art. 130(5) — 1% to the SPK and 1% to TÜBİTAK — funds the regulator's technical capacity and began in 2025 on 2024 revenue.
Sources: Law No. 7518 (Arts. 35/B(2), 99/B(2), 130(5)); SPK Communiqués III-35/B.1 & III-35/B.2 (in force March 2025); CertiK, "Turkey's CASP Framework: The TÜBİTAK Edge" (June 2026).
How the regulation evolved
From an AML backbone to a licensed, audited CASP regime.
- 2006
AML Law No. 5549
nullRegistrationIn forceTurkey's anti-money-laundering backbone. Defines obligated parties, customer identification and suspicious-transaction reporting — the duties Law 7518 later extends to crypto-asset platforms via Art. 35/C(1).
From the source:ARTICLE 29 – (1) This Law shall enter into force on the date of its publication.
Modelled onEU · 5AMLD · 2018FATF Recommendations · 2025TR-AMLLAW5549-2006· view source - 2013
Payment & E-Money Law No. 6493
nullLicensingIn forceAuthorisation regime for payment and e-money institutions, modelled on the EU's PSD2 and EMD2. Becomes the legal hook for the 2021 crypto-payment ban.
From the source:Published in the Official Gazette: Date: 27/6/2013 Issue: 28690
Modelled onEU · PSD2 · 2015EU · EMD2 · 2009FATF Recommendations · 2025TR-PAYLAW6493· view source - 2021
TCMB Crypto-Payment Ban
TCMBProhibitionIn forceProhibits using crypto-assets — directly or indirectly — in payments, and bars payment / e-money institutions from intermediating fund transfers to crypto platforms. A containment measure, not a licensing regime.
From the source:Bu Yönetmelik 30/4/2021 tarihinde yürürlüğe girer.
TR-TCMBPAYBAN-2021· view source - 2024
Law No. 7518 — CASP Framework
nullLicensingImplementingAmends the Capital Markets Law to license crypto-asset service providers under the SPK. Introduces the licensing IT-systems bar (Art. 35/B(2)), mandatory independent IT-systems audit (Art. 99/B(2)), client-asset segregation (Art. 35/C(6)-(7)) and the Travel Rule (Art. 35/C(5)).
From the source:Bu Kanunun 35/B ve 35/C maddeleri uyarınca çıkarılacak ikincil düzenlemeler, bu maddenin yürürlüğe girdiği tarihten itibaren altı ay içinde yürürlüğe konulur.
Modelled onEU · MiCA · 2023FATF Recommendations · 2025TR-LAW7518-2024· view source - 2025
MASAK Travel Rule & SPK Communiqués
MASAKLicensingImplementingOperationalises Law 7518. MASAK's Travel Rule Guidelines take effect on 25 February 2025, extending originator/beneficiary data duties to crypto-asset transfers; SPK Communiqués III-35/B.1 and III-35/B.2 (establishment, operating principles, capital adequacy) enter into force in March 2025; and TÜBİTAK BİLGEM technical guidelines set the security bar for licensing.
From the source:5549 sayılı Suç Gelirlerinin Aklanmasının Önlenmesi Hakkında Kanun, 6362 sayılı Sermaye Piyasası Kanunu ve ilgili mevzuat çerçevesinde kripto varlık hizmet sağlayıcıların (KVHS) yükümlülüklerine açıklık getirmek amacıyla hazırlanan “Kripto Varlık Hizmet Sağlayıcılar Rehberi” güncellenerek yayımlanmıştır.
Modelled onFATF Recommendations · 2025EU · MiCA · 2023TR-MASAKTRAVEL-2025· view source
What inspired it
Turkey's framework is a deliberate synthesis of EU and FATF standards, grafted onto its own financial-law backbone.
Modelled on the world
International frameworks Turkey's marquee laws were built on. These links are curated from the statutes' own references — the anchor frameworks are not seeded as graph nodes, so they do not appear in the live graph.
- AML Law No. 5549→ EU · 5AMLD (2018)
- AML Law No. 5549→ FATF Recommendations (2025)
- Payment & E-Money Law No. 6493→ EU · PSD2 (2015)
- Payment & E-Money Law No. 6493→ EU · EMD2 (2009)
- Payment & E-Money Law No. 6493→ FATF Recommendations (2025)
- Law No. 7518 — CASP Framework→ EU · MiCA (2023)
- Law No. 7518 — CASP Framework→ FATF Recommendations (2025)
- MASAK Travel Rule & SPK Communiqués→ FATF Recommendations (2025)
- MASAK Travel Rule & SPK Communiqués→ EU · MiCA (2023)
Domestic legal foundations
The Turkish statutes the CASP regime leans on, read live from the regulatory graph. Curated to the laws that matter for crypto and verified against real citation edges — the long tail of generic statute references is filtered out.
- Capital Markets Law No. 6362
The statute Law 7518 amends — CASPs are licensed and supervised as capital-market institutions under the SPK.
Cited byLaw 7518Payment Law 6493MASAK Travel Rule - AML Law No. 5549
Source of the KYC, customer-due-diligence and suspicious-transaction duties CASPs inherit through MASAK.
Cited byLaw 7518MASAK Travel Rule - Banking Law No. 5411
Client cash and crypto are custodied through BDDK-regulated banks named by the SPK.
Cited byLaw 7518Payment Law 6493 - Anti-Terror Law No. 3713
Counter-financing-of-terrorism duties that extend to crypto-asset transfers.
Cited byLaw 7518 - Proliferation-Financing Law No. 7262
Targeted financial sanctions and proliferation-financing controls applied to CASPs.
Cited byLaw 7518 - Turkish Penal Code No. 5237
Underlies the market-manipulation and fraud offences the CASP regime enforces.
Cited byLaw 7518
What the TÜBİTAK bar actually demands
Concrete technical controls a CASP must meet — and where CertiK maps.
Key material must sit in FIPS 140-3 / ISO-19790 Level-3 HSMs. Level-2 modules are explicitly insufficient.
The bulk of client assets must be held in cold storage, with hot-wallet exposure tightly bounded.
Withdrawals require multi-party computation or multi-signature, with at least one key share held inside a certified HSM.
Private keys are generated inside a secure element and must never be exported in clear.
Systems handling client assets and order flow must be hosted domestically, within Turkish jurisdiction.
Controls governing how the platform integrates with distributed-ledger networks (node, bridge and settlement security).
An SPK-listed independent audit firm must audit the platform's IT systems; procedures are set by the SPK after a TÜBİTAK opinion.
Requirements → CertiK services
Each obligation Turkey's text imposes, and the CertiK service that answers it.
- RequiredIndependent IT-systems auditLaw 7518 Art. 99/B(2)L1 Chain AuditSmart Contract AuditPenetration Testing
- RequiredIndependent certification (licensing IT bar)Law 7518 Art. 35/B(2) — TÜBİTAK criteriaIndependent CertificationSecurity Guidance
- RequiredKYC / AML & Travel RuleLaw 7518 Art. 35/C(1) & 35/C(5)SkyInsights — AML / KYTRegulatory Compliance Support
- RequiredClient-asset custody & segregationLaw 7518 Art. 35/C(6)-(7)Proof of ReservesSkynet — Threat Monitoring
- RequiredProof of reservesLaw 7518 Art. 35/C(6)-(7)Proof of Reserves
- Not flaggedPenetration testingLaw 7518 Art. 35/B(2) — IT-systems securityPenetration Testing
- Not flaggedFormal verificationLaw 7518 Art. 35/B(2)Formal Verification
The exploitable gap
Law 7518 delegates the hard technical criteria to forthcoming secondary regulation — the precise space an independent certifier fills.
The law delegates the specific technical criteria for licensing and asset listing to future regulations by the Capital Markets Board, based on input from TÜBİTAK. This creates an opportunity for certifiers to provide services based on these forthcoming technical standards.
Law No. 7518, transitional provision:Bu Kanunun 35/B ve 35/C maddeleri uyarınca çıkarılacak ikincil düzenlemeler, bu maddenin yürürlüğe girdiği tarihten itibaren altı ay içinde yürürlüğe konulur.
Aligned with the frameworks it was modelled on
Where Turkey's Law 7518 matches MiCA and the FATF standard — grounded article by article.
| Dimension | Türkiye (Law 7518) | EU · MiCA | FATF |
|---|---|---|---|
Licensing regime for CASPs Art. 35/B(1) | Yes | Yes | Partial Recommends, does not license |
IT-systems criteria set by a state technical body Art. 35/B(2) — TÜBİTAK | Yes TÜBİTAK BİLGEM | Partial DORA resilience, no state lab | No |
Mandatory independent IT-systems audit Art. 99/B(2) | Yes | Partial | No |
KYC / customer due diligence Art. 35/C(1) — Law 5549 | Yes | Yes | Yes |
Travel Rule (originator / beneficiary data) Art. 35/C(5) | Yes | Yes | Yes Recommendation 16 |
Market-abuse surveillance Art. 35/C(3) — Art. 104 | Yes | Yes | No |
Client-asset segregation / custody Art. 35/C(6)-(7) | Yes BDDK-approved banks, bankruptcy-remote | Yes | Partial |
Crypto excluded from investor compensation Art. 35/C(4) — Art. 82 | Yes Explicit exclusion | Partial | No |
How Turkey compares to the world
Technical-security prescriptiveness across the major regimes.
| Regime | Approach | Advantage | Trade-off |
|---|---|---|---|
Türkiye SPK + TÜBİTAK BİLGEM | Licensing gated by a national cybersecurity lab; prescriptive, state-grade controls (HSM level, custody architecture, local hosting). | Highest technical-security floor of any major regime; little ambiguity about what secure means. | Heavy compliance lift; prescriptive controls can lag fast-moving technology. |
Hong Kong SFC | Licensing with detailed custody and security expectations, assessed case-by-case by the regulator. | Mature, well-understood process; strong custody emphasis. | Less explicit on hardware-level cryptographic standards. |
European Union ESMA / EBA (MiCA + DORA) | Harmonised licensing (MiCA) plus operational-resilience rules (DORA); principles- and risk-based rather than device-prescriptive. | Single-market passport; broad, consistent coverage. | Technical-security expectations are outcome-based, leaving the how to firms. |
Dubai VARA | Activity-based licensing with dedicated rulebooks; security expectations set per activity. | Crypto-native, fast-moving regulator. | Younger regime; less prescriptive on cryptographic hardware. |
Other markets Various | Registration or AML-only regimes with limited technical-security mandates. | Low barrier to entry. | Weak assurance; security largely left to the platform. |
Source: CertiK, "Turkey's CASP Framework: The TÜBİTAK Edge" (June 2026).
Turkey's regulatory DNA
How rare each requirement is across the 23 tracked jurisdictions. Turkey's signature is that it mandates the scarce, technical controls most regimes never ask for.
| Requirement | Türkiye | Global adoption | Rarity |
|---|---|---|---|
| Formal verification | Not required | 0/23 | Unused |
| Penetration testing | Not required | 2/23 | Signature |
| Technical audit | Required | 8/23 | Signature |
| Independent certification | Required | 9/23 | Signature |
| Proof of reserves | Required | 11/23 | Common |
| Custody security | Required | 16/23 | Common |
| AML / KYT | Required | 21/23 | Table-stakes |
"Signature" = required by fewer than half of the tracked jurisdictions. Adoption counts read live from the corpus.
Closest regulatory peers
Ranked by rarity-weighted overlap — sharing a scarce control (independent audit, certification) counts for far more than sharing table-stakes KYC.
- Argentina89%Technical auditIndependent certificationProof of reservesCustody securityCustodyTaxation
- Technical auditIndependent certificationProof of reservesToken issuanceCustody securityCustody
- Hong Kong86%Technical auditIndependent certificationProof of reservesToken issuanceCustody securityCustody
- Technical auditIndependent certificationProof of reservesToken issuanceCustody securityCustody
- Singapore66%Independent certificationProof of reservesToken issuanceCustody securityCustodyTaxation
- Independent certificationProof of reservesCustody securityCustodyTaxationAML / KYT
Underlying norms
62 Turkish norms in the corpus that ground this view.
- MASAK Travel Rule Guidelines (Effective February 25, 2025)TR-MASAKTRAVEL-2025Licensing2025-02-25
- Law on Amendments to the Capital Markets Law (Law No. 7518)TR-LAW7518-2024Licensing2024-07-02
- Law No. 7499TR-LAW7499-20242024-03-02
- Law No. 7420TR-LAW7420-20222022-11-03
- Regulation on Payment Services and Electronic Money Issuance and Payment Service ProvidersTR-TRPSEMREG-20212021-12-01
- MASAK General Communiqué No. 18 (Designating Crypto Asset Service Providers as Obligated Parties)TR-MASAKCOMM18-2021Registration2021-05-01
- MASAK General Communiqué No. 19 on Remote Identification Methods to be Used for Customer Identification by Crypto Asset Service ProvidersTR-MASAKGENCOMM19-20212021-05-01
- Regulation on Not Using Crypto Assets in PaymentsTR-TCMBPAYBAN-2021Prohibition2021-04-16
- Law No. 7262 on the Prevention of the Financing of the Proliferation of Weapons of Mass DestructionTR-LAW7262-20202020-12-27
- 2019-11-12
- Decree Law No. 703TR-LAW703-20182018-07-02
- Law No. 7077 of 2018 on Amending Certain Laws for the Adoption of Decree-Laws Issued under the State of EmergencyTR-LAW7077-20182018-02-01
- Law No. 7061TR-LAW7061-20172017-11-28
- 2016-10-20
- 2016-04-23
- Law on the Protection of Personal Data No. 6698TR-KVKKLAW6698-20162016-03-24
- MASAK General Communiqué No. 13TR-COMMUNIQU13-20142014-06-28
- Law on the Prevention of the Financing of Terrorism No. 6415 of 2013TR-TERRORISM6415-20132013-02-07
- Capital Markets Law No. 6362TR-LAW6362-20122012-12-06
- Decree-Law No. 663 on the Organization and Duties of the Ministry of Health and its Affiliated InstitutionsTR-LAW663-20112011-10-11
- Turkish Commercial Code No. 6102 of 2011TR-CODE6102-20112011-01-13
- Turkish Code of Obligations No. 6098TR-OBLIGATIONS6098-20112011-01-11
- Electronic Communication Law No. 5809 of 2008TR-LAW5809-20082008-11-05
- Regulation on the Compliance Program for the Prevention of Laundering of Criminal Proceeds and Financing of TerrorismTR-MASAKREGULATIONONCOMPLIA-20082008-09-16
- MASAK General Communiqué No. 13 on Suspicious Transaction ReportingTR-COMMUNIQU13-20082008-04-09
- Regulation on Measures Regarding Prevention of Laundering Proceeds of Crime and Financing of TerrorismTR-MASAKAMLCFTREG-20082008-01-09
- 2006-10-11
- Law on the Prevention of Laundering Proceeds of Crime (Law No. 5549)TR-AMLLAW5549-20062006-10-11
- 2006-05-31
- Banking Law No. 5411TR-LAW5411-20052005-10-19
- Child Protection Law No. 5395TR-LAW5395-20052005-07-15
- 2005-02-10
- 2004-12-13
- Code of Criminal Procedure No. 5271TR-PROCEDURE5271-20042004-12-04
- Criminal Procedure Code No. 5271 of 2004TR-CODE5271-20042004-12-04
- 2004-11-04
- Turkish Penal Code (Law No. 5237)TR-LAW5237-20042004-09-26
- Turkish Penal Code No. 5237TR-CODE5237-20042004-09-26
- Public Financial Management and Control Law (Law No. 5018)TR-LAW5018-20032003-12-10
- Turkish Civil Code No. 4721TR-CODE4721-20012001-11-22
- 1999-12-02
- Law on the Prevention of Money Laundering No. 4208TR-LAW4208-19961996-11-13
- Anti-Terrorism Law No. 3713TR-LAW3713-19911991-04-12
- Decree-Law No. 375TR-LAW375-19891989-06-27
- Basic Law on Health Services (Law No. 3359)TR-LAW3359-19871987-05-07
- Law No. 3071 on the Exercise of the Right to PetitionTR-LAW3071-19841984-11-01
- Capital Markets Law No. 2499TR-CML2499-19811981-07-30
- Law No. 1211 on the Central Bank of the Republic of TurkeyTR-LAW1211-19701970-01-14
- Law on Attorneyship No. 1136 of 1969TR-ATTORNEYSHIP1136-19691969-03-19
- Civil Servants Law (Law No. 657)TR-LAW657-19651965-07-14
- Tax Procedure Law No. 213 of 1961TR-LAW213-19611961-01-04
- Notification Law No. 7201 of 1959TR-LAW7201-19591959-02-11
- 1953-07-21
- Enforcement and Bankruptcy Law No. 2004TR-LAW2004-19321932-06-09
- 1930-02-20
- Personal Data Protection Law (Law No. 6698)TR-KVKKLAW6698—
- Turkish Criminal Code (Law No. 5237)TR-CRIMLAW5237—
- Law on Payment and Securities Settlement Systems, Payment Services and Electronic Money Institutions (Law No. 6493)TR-PAYLAW6493Licensing—
- Banking Law (Law No. 5411)TR-BANKLAW5411Licensing—
- —
- Corporate Tax Law (Law No. 5520)TR-TAXLAW5520—
- Value Added Tax Law (Law No. 3065)TR-VATLAW3065—
Data confidence & caveats
- Analysis coverage: 21%
- Coverage breadth: 67%
- Regulator diversity: 88%
- Evidence density: 74%
- International lineage (MiCA, PSD2, EMD2, 5AMLD, FATF) is curated from the statutes' own references; these anchors are not seeded as graph nodes.
- Article citations are taken from the Turkish text of Law No. 7518; auto-translated bodies are for orientation only.
- Technical mandates reflect TÜBİTAK BİLGEM guidance and SPK Communiqués in force as of March 2025.